Anomaly detection with diagnosis in diversified systems using information flow graphs

Frédéric Majorczyk, Eric Totel, Ludovic Mé, Ayda Saïdane

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Design diversity is a well-known method to ensure fault tolerance. Such a method has also been applied successfully in various projects to provide intrusion detection and tolerance. Two types of approaches have been investigated: the comparison of the outputs of the diversified services without any knowledge of the internals of the server (black box approach) or an intrusive observation of the activities that occur on the diversified servers (gray box approach). Previous work on black-box approaches have shown that some types of attacks cannot be detected. In this paper, we introduce a gray-box approach, on the one hand to increase the detection coverage, and on the other hand to add some diagnosis capability to the IDS. Our gray-box approach is based on the comparison of information flow graphs generated by the activities on the servers.

Original languageEnglish
Title of host publicationProceedings of The Ifip Tc 11 23rd International Information Security Conference
Subtitle of host publicationIFIP 20th World Computer Congress, IFIP SEC'08
PublisherSpringer New York
Pages301-315
Number of pages15
ISBN (Print)9780387096988
DOIs
Publication statusPublished - 1 Jan 2008
Externally publishedYes

Publication series

NameIFIP International Federation for Information Processing
Volume278
ISSN (Print)1571-5736

Keywords

  • Anomaly detection
  • Anomaly diagnosis
  • COTS diversity
  • Design diversity
  • Graph similarity

Fingerprint

Dive into the research topics of 'Anomaly detection with diagnosis in diversified systems using information flow graphs'. Together they form a unique fingerprint.

Cite this